cloud.google.com
Russian Cyber Espionage Clusters Exploit OAuth and Phishing Techniques
Article Content
Google's Threat Intelligence Group (GTIG) is tracking three Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting individuals in academia, defense, and government across Europe and the U.S. These groups exploit legitimate authentication workflows, such as OAuth and app password phishing, to compromise accounts. UNC6293 impersonates U.S. State Department officials, while UNC7005 and UNC5976 employ various social engineering tactics, including fake invitations and device linking. The attacks are highly selective, often targeting fewer than 100 individuals at a time, but they pose significant risks due to their sophisticated methods. GTIG has observed these operations since at least 2025, with ongoing adaptations to their phishing techniques. The current status indicates a persistent threat as these clusters continue to evolve their tactics.
Key Points: • Three Russian cyber espionage clusters are actively targeting sensitive sectors in the U.S. and Europe. • Attack methods include OAuth abuse and app password phishing, making detection challenging. • The operations are highly selective, often involving fewer than 100 targets per campaign.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.